CompTIA Network+ (N10-009)Network SecurityHard

A penetration tester repeatedly sends spoofed 802.11 management frames to a client connected to the corporate WPA2 access point, forcing the client to disconnect. Moments later, the client automatically reconnects, and the tester captures the resulting four-way handshake for offline password cracking. Which technique did the tester use to force the reconnection?

  1. AEvil twin
  2. BDeauthentication attack
  3. CVLAN hopping
  4. DARP spoofing
Show answer & explanation

Correct answer: B. Deauthentication attack

A deauthentication attack sends forged 802.11 deauth management frames to disconnect a client from its AP, forcing a reconnection that can be captured to obtain the WPA/WPA2 handshake for offline cracking. Evil twin is a fake AP impersonation, ARP spoofing targets IP-to-MAC mappings, and VLAN hopping targets Layer 2 segmentation—none directly force a Wi-Fi client to disconnect via management frames.

Why the other options are wrong

  • A. Evil twin is an impersonating rogue AP, not a frame-based disconnect technique.
  • C. VLAN hopping exploits switch tagging, unrelated to wireless client disconnection.
  • D. ARP spoofing manipulates ARP caches on wired/wireless LANs, not 802.11 management frames.

Deauthentication Attack

A wireless attack that sends forged 802.11 deauthentication management frames to disconnect a client from its access point, often used to force a reconnection and capture the WPA handshake.

  • Exploits unauthenticated 802.11 management frames
  • Common precursor to WPA2 handshake capture for offline cracking
  • Mitigated by 802.11w (Management Frame Protection)

Memory trick: Kick them off, catch them coming back on.

More Network Security questions